
CVE-2016-15041-mainwp-dashboard
Vuln lab: MainWP Dashboard <= 3.1.2 Unauthenticated Stored XSS

Vuln lab: MainWP Dashboard <= 3.1.2 Unauthenticated Stored XSS

Grafana SQL Expressions → DuckDB LFI (CVE-2024-9264)

Explicação e demonstração da vulnerabilidade ZeroLogon (CVE-2020-1472)

PoC and explanation for CVE-2025-4517 used in a CTF I was playing.

Step-by-step walkthrough for exploiting Subrion CMS via CVE-2021-2220 on an OffSec lab machine, covering web application exploitation and flag…

CTF challenge demonstrating Django ORM filter injection (CVE-2025-64459) with auth bypass and product filter bypass exploits, including deployment…

Ansible-deployed vulnerable VM lab providing a hands-on security challenge environment for CVE-2025-46811 vulnerability research and exploitation…

Educational walkthrough for exploiting CVE-2025-55182, a React2Shell vulnerability, with step-by-step guidance for TryHackMe labs.

CVE-2019-17080

POC for CVE-2018-8097 This script exploits CVE-2018-8097 and can retrieve files and contents using a blind RCE method.

Proof-of-Concept exploit script for Xdebug 2.5.5 and earlier versions (CVE-2015-10141).

Educational CTF demo demonstrating command execution via Git hooks by abusing core.hooksPath in automation workflows. Highlights local hook execution…

CTF challenge demonstrating CVE-2024-4577 PHP CGI argument injection, with vulnerable app, attack scripts, and Kubernetes/Docker deployment for…

Manual and automated exploitation walkthrough for vsftpd 2.3.4 backdoor (CVE-2011-2523) with custom reverse shell payload and Metasploit integration…

CalderaForms 1.5.9.1 XSS (WordPress plugin) - tutorial

Deliberately vulnerable .NET web application for learning common web security flaws through hands-on exercises covering XSS, SQL injection, and other…

Privilege Escalation on HTB "Poison" using PwnKit (CVE-2021-4034)

Explicação + Lab no THM